Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Foreman MEDIUM 6.0
CVE-2015-3235

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unsp…

Fix: after 1.8.2
Fix from $1,600 2015-08-14
Foreman MEDIUM 5.0
CVE-2015-3155

Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to captu…

Fix: after 1.8.0
Fix from $1,600 2015-08-14
Foreman MEDIUM 5.0
CVE-2015-1816

Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a craft…

Fix: after 1.7.3
Fix from $1,600 2015-08-14
Foreman MEDIUM 6.4
CVE-2014-4507

Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files …

Fix: after 1.4.4
Fix from $1,600 2014-06-20
Foreman HIGH 7.5
CVE-2014-0007EPSS 9%

The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the …

Fix: after 1.4.4
Fix from $1,950 2014-06-20
Foreman MEDIUM 5.0
CVE-2014-0192

Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive inf…

Patch available
Fix from $1,600 2014-05-08
Foreman MEDIUM 6.8
CVE-2014-0090

Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.

Fix: after 1.4.1
Fix from $1,600 2014-05-08
Foreman HIGH 7.5
CVE-2013-0171

Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.

Fix: after 1.0
Fix from $1,950 2014-05-08
Foreman HIGH 7.5
CVE-2013-0210

The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Pupp…

Fix: after 1.0
Fix from $1,950 2014-05-08
Foreman MEDIUM 6.5
CVE-2013-0187

Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.

Fix: after 1.0
Fix from $1,600 2014-05-08
Foreman MEDIUM 5.0
CVE-2013-0173

Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attac…

Fix: after 1.0
Fix from $1,600 2014-05-08
Foreman MEDIUM 5.0
CVE-2013-0174

The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.

Fix: after 1.0
Fix from $1,600 2014-05-08
Foreman HIGH 7.5
CVE-2012-5648

Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to…

Fix: after 1.0
Fix from $1,950 2014-04-04